- Print
- DarkLight
- PDF
Permissions
- Print
- DarkLight
- PDF
Permissions are essential for maintaining the security and integrity of your workspace, ensuring that users have appropriate access to specific functionalities and resources. Rocket.Chat offers a robust permission-based framework to manage access across various workspace features.
Permissions are assigned to roles, and users with those roles gain the corresponding access. Workspace administrators and users with the necessary permissions can modify both roles and their associated permissions as needed. To learn about roles in detail, see Roles in Rocket.Chat.
To access the Permissions menu, go to Administration > Workspace > Permissions.
Permission updates take effect instantly without requiring users to log out, sign in again, or refresh the system.
Permissions
The permissions you can assign to a role on your workspace include the following:
The list of permissions is not comprehensive.
Name | Codebase Name | Purpose |
---|---|---|
Access Mailer Screen |
| Permission to use the Mailer Tool. |
Access Permissions Screen |
| Permission to create and edit roles and permissions. |
Add all users to a room |
| Permission to add all users to a room. |
Add Omnichannel Agents to Departments |
| Permission to assign an omnichannel agent to a department. |
Add OAuth Service |
| Permission to manage different OAuth services and apps. |
Add Team Channel |
| Permission to add channels to a team. It has been renamed to |
Move room within team |
| Permission to add an existing room to a team. |
Add Team Member |
| Permission to add members to a team. |
Add User to Any Public Channel |
| Permission to add a user to a public channel. |
Add User to Any Private Channel |
| Permission to add a user to a private channel. |
Add User to Any Joined Channel |
| Permission to add a user to a joined channel. |
Bypass rate limit for REST API |
| Permission to call API without rate limitation. See Rate Limiter. |
Archive Room |
| Permission to archive a channel. |
Assign Admin Role |
| Permission to assign a user to the admin role. Requires |
Assign Roles |
| Permission to assign roles for a user. Requires |
Auto Translate |
| Permission to use the Auto Translate Tool. |
Ban User |
| Permission to ban a user. |
Block IP Device Management |
| Permission to bulk create public channels. |
Bulk Create Users |
| Permission to bulk add users. |
Bypass time limit | ||
Call Management |
| Permission to start a meeting. Requires Video Conference -> BigBlueButton enabled. Accessible from More -> BBB Video Chat -> Start Meeting. |
Clean Channel History |
| Permission to prune a channel's messages and/or files. |
| Permission to prune a group's messages and/or files. | |
| Permission to prune direct messages and/or files. | |
Close Omnichannel Room |
| Permission to close your own Livechat channels. |
Close Other Omnichannel Room |
| Permission to close other Livechat channels. |
Convert Team |
| Permission to convert team to channel. |
Create Public Channels |
| Permission to create public channels. |
Create Direct Messages |
| Permission to start direct messages. |
Create Invite Links |
| Permission to create invite links to add members to a room |
Create Private Channels |
| Permission to create private groups. |
Create Personal Access Tokens |
| Permission to create Personal Access Tokens. Accessible from My Account -> Personal Access Tokens. |
Create User |
| Permission to create new users. Accessible from Administration -> Users. Click the + sign found on the top right-hand corner of the Users list to create a new user. |
Create Team |
| Permission to create a team. |
Create group within team |
| Permission to create private channels in a Team. |
Create channel within team |
| Permission to create public channels in a Team. |
Delete Public Channels |
| Permission to delete public channels. |
Delete Direct Messages |
| Permission to delete direct messages. |
Delete Message |
| Permission to delete a message within a channel. |
Delete Own Message |
| Permission to delete your own message. |
Delete Private Channels |
| Permission to delete private channels. |
Delete group within Team |
| Permission to delete private channels in a Team |
Delete channel within Team |
| Permission to delete public channels in a Team |
Edit Livechat Room Custom Fields |
| Permission to edit a livechat custom field. |
Delete User |
| Permission to delete users. |
Delete Team |
| Permission to delete a team |
Edit Message |
| Permission to edit a message. |
Edit Omnichannel Contact |
| Permission to edit omnichannel contact. |
Edit Other User Active Status |
| Permission to enable or disable other accounts. Accessible from Administration -> Users. |
Edit Other User Avatar |
| Permission to edit other users avatar. |
Edit Other User E2E Encryption |
| Permission to edit other users E2E key. |
Edit Other User Information |
| Permission to change other user's name, username, or email address. Accessible from Administration -> Users. |
Edit Other User Password |
| Permission to modify other user's passwords. Requires edit-other-user-info permission. Accessible from Administration -> Users. |
Edit Other User Two Factor TOTP |
| Permission to edit other user TOTP. |
Edit Privileged Setting |
| Permission to edit privileged settings. |
Edit Room |
| Permission to edit a room's name, topic, type (private or public status), and status (active or archived). |
Edit Room Avatar |
| Permission to edit a room avatar. |
Edit Room's Retention Policy |
| Permission to edit a room's retention policy. |
Edit Team |
| Permission to edit a team. |
Edit Team Channel |
| Permission to add a team channel |
Edit Team Member |
| Permission to add a team member. |
Force Delete Message |
| Permission to forcefully delete messages, independent of any deletion blocking setting. |
Inbound Voip Calls |
| |
Join Without Join Code |
| Permission to bypass join codes when entering a channel with a join code set. |
Leave Channels |
| Permission to leave the public channel. |
Leave Private Groups |
| Permission to leave the private channel. |
Logout Device Management |
| Permission to log out device. |
Logout Other User |
| Permission to log out other users. |
Mail Messages |
| Permission to use the "Mail Messages" tool in the channel actions menu. |
Manage Agent Extension Association |
| Permission to manage extension association. |
Manage Apps |
| Permission to manage all apps. Accessible from Administration -> Apps. |
Manage Assets |
| Permission to manage assets. Must also be admin Accessible from Administration -> Assets. |
manage-chatpal | ||
Manage Email Inbox |
| Permission to manage email inbox. |
Manage Cloud |
| Permission to manage cloud. Requires view-user-administration permission. Accessible from Administration -> Cloud. |
Manage Emoji |
| Permission to add custom emojis to the server. Accessible from Administration -> Custom Emoji. |
Manage Incoming Integrations |
| Permission to manage all incoming integrations. Accessible from Administration -> Integrations. |
Manage Outgoing Integrations |
| Permission to manage all outgoing integrations. Accessible from Administration -> Integrations. |
Manage OAuth Apps |
| Permission to manage OAuth apps. Accessible from Administration -> OAuth. |
Manage Outgoing Integrations |
| Permission to manage all outgoing integrations. Accessible from Administration -> Integrations. |
Manage Outgoing Integrations |
| User can create and edit own outgoing integration - webhooks. |
Manage Own Incoming Integrations |
| User can create and edit own incoming integration - webhooks. |
Manage Omnichannel Agents |
| Permission to manage omnichannel agents. |
Manage Omnichannel Canned Responses |
| Permission to manage canned responses. |
Manage Omnichannel Departments |
| Permission to manage omnichannel departments. |
Manage Omnichannel Managers |
| Permission to manage omnichannel managers. |
Manage Omnichannel Monitors |
| Permission to manage omnichannel monitors. |
Manage Omnichannel Priorities |
| Permission to manage omnichannel priorities. |
Manage Omnichannel SLA |
| Permission to manage omnichannel SLA |
Manage Omnichannel Tags |
| Permission to manage omnichannel tags. |
Manage Omnichannel Units |
| Permission to manage omnichannel units. |
Manage Moderation Actions |
| Permission to manage moderation. |
Change Some Settings |
| Permission to change settings which are explicitly granted to be changed. |
Manage Sounds |
| Permission to manage sounds. Accessible from Administration -> Custom Sounds. |
Manage User Status |
| Permission to manage user status. |
Manage Voip Call Settings |
| Permission to manage Voip call settings. |
Manage Voip Contact Center Settings |
| Permission to manage Voip contact center. |
Mention All |
| Permission to mention everyone in a channel. |
Mention Here |
| Permission to notify active users in a channel. |
Impersonate Other Users |
| Permission to impersonate other users using message alias. Accessible from Administration -> Permissions. | |
Mute User |
| Permission to mute other users in the same channel. |
On Hold Omnichannel Room |
| Permission to put a room on hold. |
On Hold Others Omnichannel Room |
| Permission to put livechat room on hold for others. |
Outbound Voip Calls |
| Permission to outbound voip calls. |
Pin Message |
| Permission to pin a message in a channel. |
Post ReadOnly |
| Permission to post messages on read-only channels. |
Preview Public Channel |
| Permission to preview public channels. |
Register On Cloud |
| Permission to register a workspace manually. |
Remove Canned Responses |
| Permission to remove canned responses. |
Remove Closed Omnichannel Room |
| Permission to close Live Chat rooms. Requires |
Remove Omnichannel Departments |
| Permission to remove omnichannel departments. |
Remove Slackbridge Links |
| Permission to remove slackbridge links |
Remove Team Channel |
| Permission to remove a channel from a team. |
Remove User |
| Permission to remove users from channels. |
Request PDF Transcript |
| Permission to request a PDF transcript for a chat. |
Restart the server |
| Permission to reset the server. |
Reset Other User E2E |
| Permission to set E2E key. See End to End Encryption. |
Run Import |
| Permission to use the data importer tools. Must also be an admin. Accessible from Administration -> Import. |
Run Migration |
| Permission to run migrations. |
Save All Canned Responses |
| Permission to save all canned responses. |
Save Canned Responses |
| Permission to save canned responses. |
Save Department Canned Responses |
| Permission to save canned responses in the right. |
Save Others Omnichannel Room Info |
| Permission to add additional information to both the visitor and Live Chat rooms. |
Send Many Messages |
| Permission to bypasses rate limit of 5 messages per second. |
Send Omnichannel Conversation Transcript |
| Permission to send omnichannel transcript. |
Set Leader |
| Permission to set leaders for channels |
Set Moderator |
| Permission to set moderators for channels. |
Set Owner |
| Permission to set other users as owner of a public channel. |
Set React When ReadOnly |
| Permission to react to messages in only channels. |
Set ReadOnly |
| Permission to set room read-only. Accessible from Room Info -> Edit. |
Snippet Message |
| Permission to create message snippets. |
Spy Voip Calls |
| |
Start Discussion |
| Permission to start a discussion. |
Start Discussion (Other-User) |
| Permission to start a discussion, which permits the user to create a discussion from a message sent by another user as well. |
Sync authentication services' users |
| Permission to sync users from other authentication services to the workspace. |
Toggle Room E2E Encryption |
| Permission to toggle E2E encryption. |
Unarchive Room |
| Permission to unarchive channels. |
User Generate Access Token |
| Permission to create authorization tokens for users. |
Ring other users when calling |
| Permission to ring other users when calling. |
View Agent Canned Responses |
| Permission to view canned responses of an agent. |
View Agent Extension Association |
| Permission to view agent extension association. |
View All Canned Responses |
| Permission to view all canned responses |
View All Team Channels |
| Permission to view all team's channels |
View All Teams |
| Permission to view all teams |
View Members List in Broadcast Room |
| Permission to view the list of users in a broadcast channel. |
View Public Channel |
| Permission to view public channels. |
View Direct Messages |
| Permission to view direct messages. Does not affect the ability to begin/start a direct message with another user. |
View Device Management |
| Permission to view device management dashboard |
View Engagement Dashboard |
| Permission to view engagement dashboard. |
View Federation Data |
| Permission to view federation data |
View Full Other User Info |
| Permission to view full profile of other users including account creation date, last login, etc. |
View Import Operations |
| Permission to view import operations |
View Join Code |
| Permission to view the join code of channels. |
View Joined Room |
| Permission to view current joined channels. |
View Omnichannel Rooms |
| Permission to view Live Chat channel. |
View Omnichannel Analytics |
| Permission to view Live Chat analytics. Requires Live Chat feature enabled and |
View Omnichannel Appearance |
| Permission to view live chat appearance. |
View Omnichannel Business-Hours |
| Permission to view live chat business hours. |
View Omnichannel Current Chats |
| Permission to view live chat current chats |
View Omnichannel Custom Fields |
| Permission to view Omnichannel custom fields. |
View Omnichannel Departments |
| Permission to view Omnichannel departments. |
View Omnichannel Installation |
| Permission to view Omnichannel installation |
View Omnichannel Manager |
| Permission to view other Live Chat managers. |
View Omnichannel Queue |
| Permission to view Omnichannel queue |
View Omnichannel Real-time Monitoring |
| Permission to view livechat real-time monitoring. |
View Omnichannel Rooms closed by another agent |
| Permission to view live chat rooms closed by another agent. |
View Omnichannel Rooms closed by another agent in the same department |
| Permission to view live chat rooms closed by another agent in the same department. |
View Omnichannel Rooms |
| Permission to view a list of Live Chat channels. |
View Omnichannel Triggers |
| Permission to view live chat triggers. |
View Omnichannel Webhooks |
| Permission to view live chat webhooks |
View Logs |
| Permission to view logs. Accessible from Administration -> View Logs. |
View Moderation Console |
| Permission to view the moderation console of the server. |
View Omnichannel Contact Center |
| Permission to manage access to the contact center. |
View Other User Channels |
| Permission to manage channels on the admin screen. |
View Outside Room |
| Permission to find new channels and users. Users without this permission won't see channels that they are not part of when searching using the spotlight. |
View Private Room |
| Permission to view private channels. |
View Privileged Setting |
| Permission to view privileged settings. |
View Room Administration |
| Enables Administration -> Channels module. Enables Permission to view public, private, and direct message statistics. Does not include permission to view conversations or archives. |
View StatisticsView User Administration |
| Enables Administration -> Info module. Enables the permission to view system statistics such as number of users logged in, number of rooms, operating system information. |
View User Administration |
| Enables Administration -> Users module. Only includes partial, read-only list view of other user accounts currently logged into the system. No user account information is accessible with this permission. Add view-full-other-user-info to see a complete list of other users via the Administration -> Users. |
Manage Voip Extension |
| Permission to manage VoIP extensions assigned to users |
View VoIP Extension Details |
| Permission to see contact information during calls |
View User VoIP extension |
| Permission to access user-facing features in the Team Voice Calls (VoIP) interface, excluding administrative controls. Without this permission, voice calling functionality will be disabled for the user |
Can Audit |
| Permission to access the Message Auditing Panel |
Can Audit Log |
| Permission to check the details about who used the Message Auditing Panel and their search results |
Allow file upload on mobile devices |
| Permission to allow mobile users to upload files to the workspace. |
By carefully managing permissions, administrators can provide a safe space for collaboration. As we move on to the next section, we'll discuss managing permissions for workspace settings.